
Introduction 55
VPN on the OnSite
In summary, you can use the VPN features on the OnSite to create the two
following types of connections:
• Create a secure tunnel between the OnSite and a gateway at a remote
location so every machine on the subnet at the remote location has a
secure connection with the OnSite.
• Create a secure tunnel between the OnSite and a single remote host
The gateway in the former example and the individual host in the second
example both need a fixed IP address.
To set up a security gateway, you can install IPsec on any machine that does
networking over IP, including routers, firewall machines, various application
servers, and end-user desktop or laptop machines.
The ESP and AH authentication protocols are supported. RSA Public Keys
and Shared Secret are also supported.
The following table describes the parameters that must be configured for a
VPN connection. The left column gives the names used in the Web Manager
and the OSD separated by a slash, unless the names are the same. Work with
the user who needs to make the VPN connection to make sure the information
matches exactly on both ends.
Table 1-25: Field and Menu Options for Configuring a VPN Connection
Parameter Names: Web
Manager/OSD
Definition
Connection Name
Any descriptive name you want to use to identify this
connection such as “MYCOMPANYDOMAIN-VPN.”
Authentication
Protocol/Protocol
The authentication protocol used, either “ESP”
(Encapsulating Security Payload) or “AH” (Authentication
Header).
Authentication Method
Authentication method used, either “RSA Public Keys” or
“Shared Secret.”
Boot Action
The boot action configured for the host, “Ignore,” “Add,”
and “Start.” “Ignore” means that VPN connection is ignored.
“Add” means to wait for connections at startup. “Start”
means to make the connection.
Commenti su questo manuale